XP DSL problems
Posted: 09-05-2003, 06:49 PM
and seem to be getting nowhere.
We provide secure email services, using SASL_AUTH, Stunnel, and SSL, via
mail clients, and HTTPS webmail. Some (not all) of our users who connect
using DSL/PPPoe/XP (this issue affects ONLY XP boxes), can receive messages
with no problem, but cannot send messages, by mail client or HTTPS.
Here are the particulars.
Almost all use XP and DSL, or a variant of DSL. It's not an ISP issue, as
our users are from every corner of the earth. DSL providers include Verizon,
Charter, Sympatico, CN Net, PacBell, Bell Atlantic, SBC, Telstra/BigPond,
and many others.
It's not a modem issue, that we can tell, as users have just about every
make and model of modem available.
The problem appeared about the 10th of August, mostly in the Far East, then
gradually seemed to spread to users in Europe, Australia, New Zealand, and
finally to those in North America.
The exception is usually the ability to send very small messages, containing
one or two words, but when the message size increases to what would be
considered a 'normal' size, the connection simply times out on the user's
computer.
From the servers, we have observed that the authentication process takes
place as it should, and that the connection is established. However, the
session is always 'unexpectedly terminated' by the client, with zero bytes
received.
Users report that they can also connect to other SSL sites without
difficulty, but that they cannot send, or POST any data.
Using the exact same computer, but substituting a dial-up connection, the
problem disappears. In other words, this is NOT a firewall or A/V issue.
All of our switchgear is Cisco, and we have tested to make sure that the MTU
isn't an issue. Our equipment, and that of our peers, all accepts an MTU of
1472, or greater. Regardless, we have had our users change the MTU in XP (to
1400). Still no joy.
We're reasonably sure that all this has to do with ICMP packets being
dropped as a response to the recent Blaster problems, as most users report
an inability to ping or trace through their connections.
Has anyone run into this and, hopefully, found a solution? Extensive
registry edits are a wee bit scary, as some of these folks speak English as
a second language, if at all.
Many thanks, in advance.
Ohda



Linear Mode

